- Gone Phishing
- Posts
- WhiteSnake infoStealer malware infiltrates Windows machines
WhiteSnake infoStealer malware infiltrates Windows machines

Welcome to Gone Phishing, your daily cybersecurity newsletter that makes cybercriminals cry like a lovely dose of ceramic magic makes the big bald(ing) bloke from The Great Pottery Throw Down cry π If you know, you know π
Todayβs hottest cybersecurity news stories:
π WhiteSnake infoStealer malware infiltrates Windows machines π»
π¨βπ» Trickbot malware dev sentenced to 64 months in prison. YAY! π
π Data theft plagues U.S. K-12 schools after holiday season attacks π
Hackers: Here I go again on Py-thoneee π€ππ
π¨ Cybersecurity Alert: Python Package Index Threat! π¨
Cybersecurity experts have identified malicious packages on the PyPI repository, delivering WhiteSnake Stealer malware to Windows systems. Threat actor "WS" uploaded packages like nigpal, figflix, and seGMM.
π» How it Works
These packages carry Base64-encoded source code in their setup.py files. Once installed, they drop a malicious payload, infecting Windows with WhiteSnake Stealer and compromising Linux hosts with a data-harvesting Python script.
π― Targets and Payloads
WhiteSnake Stealer on Windows steals info, communicates via Tor, and targets web browsers, crypto wallets, and apps like Discord. PYTA31, the threat actor, aims to exfiltrate sensitive data, including crypto wallet information.
π Advanced Tactics
Some packages use clipper functionality to replace clipboard content with attacker-owned wallet addresses for unauthorised transactions. Others steal data from browsers, apps, and crypto services.
π€― Worrying Trend
Fortinet warns of a single author disseminating multiple info-stealing malware packages on PyPI, each with distinct payload intricacies.
π Broader Issue
ReversingLabs finds similar threats on npm package registry using GitHub to store stolen SSH keys.
Stay vigilant! π‘οΈ Update your security measures and be cautious with package installations. Report suspicious activity ASAP! π

Learn AI in 5 minutes a day. We'll teach you how to save time and earn more with AI. Join 400,000+ free daily readers for trending tools, productivity boosting prompts, the latest news, and more.

It's tricky to rock a rhyme, to rock a rhyme that's right on time, it's Trickbot πΆ
π Justice Served: TrickBot Malware Developer Sentenced! π
Russian National Behind Bars: Vladimir Dunaev, aka FFX, extradited to the U.S. in October 2021, has been sentenced to 64 months in prison for his role in developing and distributing the notorious TrickBot malware.
π¨ββοΈ Legal Journey
Dunaev, a TrickBot gang developer since 2016, faced charges for computer fraud, identity theft, wire fraud, and bank fraud. He pleaded guilty on November 30, 2023.
π Global Arrest Drama
Initially arrested at Seoul International Airport in August 2021, Dunaev faced an unexpected passport expiration hurdle after being stuck in South Korea due to COVID-19 lockdowns and travel cancellations.
π» TrickBot's Dark History
TrickBot, a Windows banking Trojan since 2016, evolved with new features, infecting millions of computers globally. It initially collaborated with Ryuk ransomware and later with Conti Ransomware gang for network access.
π° Financial Impact
Dunaev's actions led to over $3.4 million in fraud, affecting victims in the Northern District of Ohio, including schools and a real estate company.
π¨ Global Effort for Justice
The FBI Cleveland Field Office emphasises the case's significance, highlighting collaboration among domestic and international partners to bring cybercriminals to justice.
βοΈ Strong Message Sent
Special Agent in Charge Greg Nelsen stresses that this sentencing sends a robust message to cybercriminals, demonstrating the commitment to combating malicious intent.
Stay vigilant against cyber threats! π‘οΈ Update your security measures and report any suspicious activity. π

π£ Catch of the Day!! πππ¦
π The Motley Fool: βFool me once, shame on β shame on you. Fool me β you can't get fooled again.β Good olβ George Dubya π Let us tell whoβs not fooling around though; thatβs the CrΓΌe π at Motley Fool. Youβd be a fool (alright, enough already! π) not to check out their Share Tips from time to time so your savings can one day emerge from their cocoon as a beautiful butterfly! π Kidding aside, if you check out their website theyβve actually got a ton of great content with a wide variety of different investment ideas to suit most budgets π€ (LINK)
π΅ Wander: Find your happy place. Cue Happy Gilmore flashback ποΈβ³πποΈ Mmmm Happy Placeβ¦ π So, weβve noticed a lot of you guys are interested in travel. As are we! We stumbled upon this cool company that offers a range of breath-taking spots around the United States and, honestly, the website alone is worth a gander. When all you see about the Land of the free and the home of the brave is news of rioting, looting and school shootings, itβs easy to forget how beautiful some parts of it are. The awe-inspiring locations along with the innovative architecture of the hotels sets Wander apart from your run of the mill American getaway ποΈπ (LINK)
π Digital Ocean: If you build it they will come. Nope, weβre not talking about a baseball field for ghosts βΎπ»πΏ (Great movie, to be fair π). This is the Digital Ocean whoβve got a really cool platform for building and hosting pretty much anything you can think of. If you check out their website youβll find yourself catching the buzz even if you canβt code (guilty π). But if you can and youβre looking for somewhere to test things out or launch something new or simply enhance what youβve got, weβd recommend checking out their services foβ sho π And how can you not love their slogan: Dream it. Build it. Grow it. Right on, brother! πΏ (LINK)

The kids arenβt alright πππ
π¨ Education Under Siege: U.S. Schools Battling Cyber Threats! π
Post-holiday season, K-12 schools across the U.S. face an alarming surge in cyberattacks and data thefts. Butte School District in Montana, Edmonds School District in Washington, Fullerton Joint Union High School District, and Glendale Unified School District in California have all reported data breaches.
π Ransomware Hits Ohio's Groveport Madison Schools
Groveport Madison Schools, Ohio, battled a ransomware attack, enduring a month-long recovery. The hackers, self-identified as BlackSuit, a suspected rebrand of the Royal ransomware gang, stole staff data. Despite disruptions, the district managed to fully recover, serving about 6,000 students in Franklin County.
π Rapid Response
Superintendent Jamie Grube acknowledged the prompt warning from the Cybersecurity and Infrastructure Security Agency (CISA). Though internet access was shut down, damage was inflicted on Windows devices, security cameras, and printers. Grube assured no compromise of student or staff data occurred.
π Vulnerabilities Unearthed
As schools embrace cloud-based platforms, cybersecurity researchers, like vpnMentor's Jeremiah Fowler, uncover vulnerabilities. Fowler exposed millions of records from school security company Raptor Technologies, revealing incident response plans, school layouts, and sensitive information on at-risk students. Lawyers are now seeking affected individuals, and the D.C. public school system notifies parents of potential student information exposure.
π‘οΈ Growing Concerns
The increasing reliance on cloud platforms leaves educational institutions susceptible to cyber threats. Immediate actions, like suspending compromised software, are crucial to safeguard sensitive information.
π©βπ« Education's Digital Defense
As schools navigate the digital landscape, continuous vigilance, rapid response, and cybersecurity measures are essential to protect the integrity of education. Stay informed and report any suspicious activity promptly! π
Thatβs all folks βοΈ

ποΈ Extra, Extra! Read all about it!
Every few weeks, we carefully select three hot newsletters to show you. Reputation is everything, so any links we share come from personal recommendation or carefully researched businesses at the time of posting. Enjoy!
The GeekAI: A daily 3 min newsletter on what matters in AI, with all the new AI things coming to market its good to stay ahead of the curve.
Wealthy Primate: Want to earn over $100k a year in IT or cybersecurity? 20 year veteran 'Wealthy Primate' might be able to help you climb that tree ππ΄ with his stick and banana approach ππ
Techspresso: Receive a daily summary of the most important AI and Tech news, selected from 50+ media outlets (The Verge, Wired, Tech Crunch etc)
Let us know what you think!
So long and thanks for reading all the phish!
Give us a rating? |

